MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 70d577aba943b783ec606abcfa912bf97c9fd4f22d5e46ff1d718d350a8e4fcc. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



FormBook


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 70d577aba943b783ec606abcfa912bf97c9fd4f22d5e46ff1d718d350a8e4fcc
SHA3-384 hash: d383ad8180a389a6148c0ddafbbb0a0165e5983f762388729c506dd3840f20c09238a976d1a51cd7d72df4799bb66b7a
SHA1 hash: eeb333da2d260c042812b7a1d8ce20d40fdf0b48
MD5 hash: c2477ce37fd1fc5932fd6fc0ebaa453f
humanhash: oregon-twenty-avocado-stairway
File name:doc00001782 swift customer remittance advice - 03182020 .exe
Download: download sample
Signature FormBook
File size:77'824 bytes
First seen:2020-03-20 06:30:03 UTC
Last seen:2020-03-20 12:35:27 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 0b20a01145062ccb8b04fb7bb0fd9b0b (1 x FormBook)
ssdeep 768:s91rCIvBv5H7lpfeUTTUbpqti6RZm4DAuTpFJ17mNUk/lMbkrs1k:suKXxpfeCeqtiF4Ddbz7mJ+Irz
Threatray 4'832 similar samples on MalwareBazaar
TLSH DB736D47F760EC65C816C73D3C6AD79122137D686981DA8B37D4BB0F68F00A28F5AB58
Reporter cocaman
Tags:exe FormBook

Intelligence


File Origin
# of uploads :
3
# of downloads :
88
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Fareit
Status:
Malicious
First seen:
2020-03-20 12:12:00 UTC
File Type:
PE (Exe)
Extracted files:
6
AV detection:
26 of 31 (83.87%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Other

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_NXMissing Non-Executable Memory Protectioncritical
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
Reviews
IDCapabilitiesEvidence
VB_APILegacy Visual Basic API usedMSVBVM60.DLL::EVENT_SINK_AddRef

Comments